https://seclists.org/oss-sec/2026/q3/651: Vulnerabilities fixed in libxml2-2.15.4
Published Sep 4, 2026
·Updated
Affected Software
1 affected component
libxml2=2.15.4
Frequently Asked Questions
1
Which parts of libxml2 are implicated by these fixes?
The release notes identify fixes in xmlregexp, dict.c, uri.c, valid.c, xpointer, xmlIO, and xinclude handling.
2
What vulnerability classes were addressed?
The listed fixes include an out-of-bounds read, missing overflow checks, an integer-overflow check before invoking a write callback, and a null-check ordering correction before calculating a string length.
3
Is there enough information to determine exploit prerequisites or affected configurations?
No. The available information does not describe attack vectors, required inputs, privileges, affected configurations, or whether default deployments are exposed.
4
What mitigation is documented if an update cannot be applied immediately?
No interim mitigation or workaround is provided in the available release-note excerpt.